Package Health

liquidstack/base

The package includes tests, a substantial README, and active build and security tooling. Its license metadata conflicts with the detected MIT file, and the project is only seven days old with all recent commits from one contributor.

Latest v1.1.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The artifact contains an MIT license file, so the release is licensed, but the manifest declares it proprietary and does not match the detected license. That conflict reduces transparency for consumers.

Release historycaution

The package is only 7 days old with 4 releases, all in the last 12 months, and releases are clustered roughly 25 minutes apart. This shows active initial development but provides little evidence of long-term maintenance.

Repo bus factorcaution

One contributor made all 4 commits in the last 3 months, leaving no demonstrated contributor redundancy. This increases continuity risk if that maintainer becomes unavailable.

Repo commit activitycaution

The repository has 4 commits in the last 3 months, so there is recent activity, but the volume is modest for a newly published package and does not yet demonstrate durable maintenance.

Security policycaution

The repository has no security policy. This is a transparency and reporting gap, though it is not by itself evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
liquidstack/blog
Version *
liquidstack/core
Version ^1.31
vlucas/phpdotenv
Version ^5.6
phpmailer/phpmailer
Version ^6.9
liquidstack/webadmin
Version *

Weekly Downloads

Info

Last Published
2 days ago
Created
10 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform